Licensed CPA Firm

SOC 2 Reporting

Independent SOC 2 examinations for cloud providers, SaaS companies, and IT service organizations.

  • Partner-led engagement, start to finish
  • Final report issued within 5 to 7 weeks of period end
  • Licensed CPA firm operating under AICPA attestation standards
Connect with an Expert

SOC 2 is a framework used to show your customers how you protect their data. We conduct SOC 2 engagements under AICPA standards, independently testing your controls against the Trust Services Criteria and issuing an opinion your customers and their security teams can rely on. If you want the examination itself unpacked first, our SOC 2 compliance audit page covers what gets tested and who is allowed to test it.

Security & Availability

Independent assessment of your controls against the AICPA Trust Services Criteria, covering how your organization addresses security, availability, and other categories relevant to your customers.

Independent Assurance

Verified by a licensed CPA firm under AICPA SSAE standards, not a self-assessment or platform-generated badge.

Customer Trust

Close deals faster by giving enterprise buyers the independent evidence they require before signing contracts.

Competitive Advantage

A SOC 2 Report removes a major procurement barrier and signals operational maturity to partners and prospects.

AICPA SOC for Service Organizations seal

Licensed AICPA CPA Firm
Authorized to issue SOC 2 Reports under AICPA SSAE No. 18 and subsequent standards

Trust Services Criteria

What a SOC 2 Report covers

SOC 2 engagements assess your controls across the AICPA Trust Services Criteria. Security is required; additional categories are selected based on your commitments to customers.

Security (Required)

Controls protecting against unauthorized access, both logical and physical. The foundation of every SOC 2 engagement.

Availability, Integrity, Confidentiality & Privacy

Additional criteria selected based on your service commitments. We help you determine which apply to your environment and customer expectations.

Which Report, and When?

A staged path, not a single audit

Very few companies jump straight to the report their buyers want. SOC 2 is a sequence of stops, each one feeding the next, and the right place to start depends on how mature your controls are today. Handed a request for a SOC 1 instead? Our SOC 1 vs SOC 2 guide untangles which report your customer actually means.

  1. Starting Point

    Readiness Assessment

    4 to 8 weeks

    Scout the route before the meter is running. We measure what you already have in place against the Trust Services Criteria and leave you a prioritized gap list to close on your own schedule, with no opinion issued and nothing reportable hanging over the work.

    Best if you have never been through a SOC 2, or you suspect a few of your controls exist more on paper than in practice.

    Start with readiness →
  2. First Milestone

    SOC 2 Type I

    1 to 2 months

    A point-in-time opinion covering whether your controls are suitably designed as of a single date. No other report gets a CPA's signature in front of a buyer sooner.

    Best if a security questionnaire is holding up a signature and a Type II observation window has not had time to run.

    Compare Type I and Type II →
  3. The Destination

    SOC 2 Type II

    Typically 6 to 12 months

    Evidence that your controls operated across an observation window, not just that they existed on one good day. A first window can be as short as 3 months. This is the report enterprise buyers ultimately require, renewed annually.

    Best if enterprise buyers sit in your pipeline; their vendor-risk teams rarely accept anything less.

    How we run the examination →

The map does not end at Type II

Renewal is annual, which turns the audit into a standing relationship rather than a transaction. Expect three things from us between report cycles: a partner who answers year-round, not only during fieldwork; early word when the AICPA updates SOC 2 guidance; and, once your Type II is issued, the option of a SOC 3 companion report you can share publicly with no NDA.

Not sure which stop is yours?

Take the two-minute quiz →

No email required. Instant results.

Side by Side

SOC 2 Type 1 vs Type 2 at a Glance

The two reports differ on six practical dimensions: what the auditor opines on, when the evidence comes from, how deep the testing goes, what your customers will accept, what the engagement costs, and how quickly you have a report in hand.

Comparison of SOC 2 Type 1 and SOC 2 Type 2 reports across six dimensions
DimensionSOC 2 Type 1SOC 2 Type 2
What the auditor opines onSuitability of control design as of a specific dateControl design plus operating effectiveness across the full period
TimingPoint-in-time snapshotObservation period, typically 6 to 12 months; a first period can be as short as 3 months
Evidence depthWalkthroughs and a single instance of each controlSamples pulled from the entire period for each control
What customers acceptEarly proof, often paired with a commitment to deliver a Type 2The report most enterprise security teams expect for ongoing relationships
Relative costLower, since testing is limited to designHigher, since every control is tested across the observation period
Time to a report in handWeeksMonths, driven by the length of the observation period

Because a Type 2 requires sampling evidence from every part of the period, it involves substantially more testing than a Type 1. That is why it costs more, and why it carries more weight with the people reading it. Both engagement types are quoted as fixed fees at Sage Audits; our pricing page explains how we scope them.

What to Expect

How a SOC 2 Engagement Works

Every engagement is partner-led and fixed-fee. Here is what the journey looks like, from first call to report in your hands.

01

Week 1-2

Scoping & Planning

We discuss your services, systems, control objectives, subservice organizations, and target report date. You receive a detailed engagement plan and request list.

02

1 to 6 months, with remediation

Readiness Assessment

For first-time engagements: we identify control gaps, map controls to the Trust Services Criteria, and deliver a prioritized remediation roadmap before your audit period begins.

03

Concentrated 3 to 4 week window

Fieldwork & Testing

Evidence collection, control testing, and interviews, concentrated late in the audit period. We schedule around your operational peaks and work directly with control owners throughout.

04

Draft ~2 weeks after fieldwork

Report Delivery

You receive a polished draft reviewed for consistency, accuracy, and clarity, with the final report issued within 5 to 7 weeks of period end. We debrief on findings and coordinate with your clients' auditors as needed.

05

Year-round

Ongoing Support

We stay involved after report delivery, helping with auditor questions, control updates, and keeping you ready for the next audit cycle.

Your Customers Are Asking for Proof. Give Them Something That Holds Up.

Book a Free 30 Minute Consultation

GRC Platform Compatible

Already using a compliance automation platform? We work with your existing stack, collecting evidence from your tools and making the most of what is already there. Bring your platform. Our approach follows AICPA guidance on the use of software tools in SOC 2 examinations.

Vanta Drata Secureframe TrustCloud + others

Our Services

SOC 2 Engagement Options

Whether you're preparing for your first SOC 2 or renewing an existing report, we work directly with your team through every phase. No handoffs to junior staff, no surprises at the finish line. Learn more about our firm

Not sure whether you need SOC 2 or whether a Type I or Type II is right for you? Take our two-minute quiz or reach out for a quick conversation.
Recommended First Step

SOC 2 Readiness / GAP Assessment

Maps your controls to the Trust Services Criteria and identifies documentation gaps before your audit period starts.

The right starting point for organizations pursuing their first SOC 2 or returning after significant environment changes. Surfaces gaps, clarifies scope, and delivers a prioritized remediation roadmap before the clock starts.

As part of this assessment, we will:

  • Review existing policies, procedures, and control documentation
  • Define system boundaries and determine appropriate scope
  • Map current controls to the Trust Services Criteria (Security and additional categories)
  • Interview control owners to understand how your environment operates day-to-day
  • Identify gaps and missing evidence affecting audit readiness
  • Provide guidance on drafting the system description
  • Deliver a prioritized control listing with remediation guidance
Point-in-Time Report

SOC 2 Type I

Point-in-time assessment of control design. A practical first step if you need a report quickly while building toward Type II.

Evaluates whether your controls are suitably designed to meet the Trust Services Criteria as of a specific date. Provides an independent CPA opinion on your control environment and can satisfy customer requests while you prepare for a full Type II.

The Type I report includes:

  • Management's description of your system and its boundaries
  • An independent CPA opinion on whether controls are suitably designed
  • Assessment against your selected Trust Services Categories
Ongoing Annual Report

SOC 2 Type II

Tests control design and operating effectiveness over an audit period of typically 6 to 12 months. Required by most enterprise customers.

The standard most enterprise buyers and security teams require. Assesses both the design and operating effectiveness over an audit period, providing the most comprehensive independent assurance that your controls work consistently over time.

Each Type II report includes:

  • Management's description of the system and boundaries, reviewed for fairness
  • Independent control testing across the full audit period, not just a snapshot
  • An opinion on both the design and operating effectiveness of controls
  • Optional framework mapping (NIST CSF, ISO 27001, HIPAA, etc.) where relevant
Available Add-On

SOC 2 + Additional Framework Mapping

Map your SOC 2 controls to additional compliance frameworks within a single engagement, reducing duplication and maximizing your audit investment.

Frameworks we currently map alongside SOC 2:

  • NIST Cybersecurity Framework (CSF): widely referenced by enterprise procurement and risk teams
  • SOX ITGC: for service organizations supporting publicly traded company financial reporting

How It Works

Our Audit Process

Every engagement follows a structured, phased approach. You always know where things stand, what is next, and what is expected.

See Full Process Details
1

Scoping & Planning

Week 1-2

We discuss your services, systems, control objectives, subservice organizations, and target report date. You receive a detailed engagement plan and request list.

2

Readiness Assessment Optional

1 to 6 months, with remediation

For first-time engagements: we identify control gaps, map controls to objectives, and deliver a prioritized remediation roadmap before your audit period begins.

3

Fieldwork & Testing

Concentrated 3 to 4 week window

Evidence collection, control testing, and interviews, concentrated late in the audit period. We schedule around your operational peaks and work directly with control owners throughout.

4

Report Delivery

Draft ~2 weeks after fieldwork

You receive a polished draft reviewed for consistency, accuracy, and clarity, with the final report issued within 5 to 7 weeks of period end. We debrief on findings and coordinate with your clients' auditors as needed.

5

Ongoing Support

Year-round

We stay involved after report delivery, helping with auditor questions, control updates, and keeping you ready for the next audit cycle.

The People Behind the Report

We specialize in systems, infrastructure, and technology. We are a firm built intentionally small so that standard never slips.

Jordan Novak, Managing Partner at Sage Audits

Jordan Novak

Managing Partner

Tasya Novak, Managing Director at Sage Audits

Tasya Novak

Managing Director

Intentionally Small, By Design

We don't scale by adding junior staff to your engagement. We stay involved because that's the only way to consistently deliver work worth standing behind. Meet the team.

Auditing Technology with Technology

We use modern tools to streamline evidence collection and reduce back-and-forth. Faster timelines, fewer disruptions. See how we avoid audit pain points.

A Process Built Around Your Engagement

No two audits run the same way because no two environments are the same. Learn about our process.

Transparent Pricing

Get Your 
Custom Quote

Our pricing is structured and fixed-fee. What drives it is the complexity of your environment, the key vendors that support your system, and the commitments you have made to customers, along with how you want those aligned to the Trust Services Categories you put in scope. Share a few details about your situation and we will follow up personally, usually with a quick call, to walk through scope and get you a clear fixed quote you can plan around.

Why Sage Audits

Big Four Training, Boutique Attention


20+Years of combined IT audit experience
0Junior staff on your engagement

Sage Audits is a licensed Colorado CPA firm and AICPA member serving SaaS and B2B technology companies nationwide.

Get a Fixed-Fee Quote

People

Work With the Partner Who Signs

A partner runs your engagement from scoping through report delivery, and the person signing the opinion is the person you talk to.

Pricing

Know Your Fee Before Work Begins

One fixed fee, quoted before work begins, with no hourly meters.

Platform

Keep the Stack You Already Run

Vanta, Drata, Secureframe, or spreadsheets: we start from the evidence you already have and build from there.

Timeline

Get the Draft in Two Weeks

Draft report within 2 weeks of fieldwork completion and the final report within 5 to 7 weeks of period end.

SOC 2 Frequently Asked Questions

Answers to the questions we hear most often from CTOs, VPs of Engineering, and compliance leads evaluating SOC 2 for the first time.

Talk to a Partner

A SOC 2 Type I typically takes approximately one to two months from kickoff to report issuance, assuming controls are in place. A SOC 2 Type II depends on your examination period (6 to 12 months), with a draft report within two weeks of fieldwork completion and the final report within five to seven weeks of period end.

For a first-time engagement, total timeline from kickoff to final report is typically 8 to 16 months depending on how much remediation you need and your audit period length. Renewals run shorter because the readiness work falls away.

SOC 2 pricing is driven by the report type, the Trust Services Categories in scope, and the size and complexity of your environment, so a meaningful number requires scoping rather than a rate card. Directionally: a readiness assessment costs less than an audit, a Type I costs less than a Type II, and every category you add beyond Security expands testing and cost. We frequently offer package pricing when readiness, Type I, and Type II work are engaged together.

We provide a fixed-fee proposal scoped to your actual environment, so there are no billing surprises. Use our pricing calculator for an estimate, or request a quote →

No. A Type I is not a prerequisite for a Type II. Many organizations go directly to a Type II, especially if they have strong controls in place. A Type I is most useful when you need a report quickly to satisfy a customer requirement while your Type II audit period runs concurrently.

Security (CC criteria) is required in every SOC 2 Report. Additional categories, Availability, Processing Integrity, Confidentiality, and Privacy, are optional and selected based on your service commitments and what your customers care about.

Most companies start with Security only; Confidentiality is the most common addition, and Availability comes next, especially for SaaS. We help you determine the right scope during our initial scoping call so you are not over- or under-audited. Read our breakdown of all five categories.

Yes. We work directly within your GRC platform throughout the engagement. We pull evidence from Vanta, Drata, Secureframe, TrustCloud, and similar tools, and we will tell you exactly what evidence format we need so collection is as lightweight as possible. Using a GRC platform does not reduce audit rigor, it reduces the manual burden on your team.

That is exactly what a readiness assessment is for. We identify gaps before your audit period begins so you have time to remediate. Discovering gaps during the audit is far more disruptive and costly. Our readiness engagements are structured to give you a clear, prioritized action list, not a generic checklist.

You work directly with a partner from scoping call through final report delivery. We do not hand off engagements to junior staff after the kickoff. The partner who scopes your engagement leads fieldwork, reviews findings, and signs the report.

With preparation, fieldwork is a concentrated 3 to 4 week window. The most common pain point is evidence collection, which GRC platforms significantly reduce. We provide a detailed evidence request list upfront, with clear format requirements, so your team is not fielding unclear back-and-forth requests during the audit.

A SOC 2 Report contains: management's description of the system, including boundaries and service commitments; the auditor's opinion letter; a description of tests performed and the results; and, for Type II, a summary of any exceptions or noted deviations.

The report is confidential and shared only with customers and stakeholders under NDA. It is not a public certification, though many companies note their SOC 2 status publicly.

SOC 2 covers overlapping control domains with ISO 27001 and HIPAA. Many of the controls you implement for SOC 2 directly support HIPAA Security Rule compliance or ISO 27001 certification. Today we map SOC 2 control environments to NIST CSF and SOX ITGC within the same engagement; ISO 27001 and HIPAA mappings are on our roadmap and can be scoped by amendment, giving your customers and partners a broader view of your compliance posture without doubling your audit effort.

SOC 2 Type II reports are issued for a specific audit period and typically renewed annually. Most enterprise customers and vendor security questionnaires expect a report dated within the last 12 months. Annual renewals are generally faster and more efficient than the initial engagement because the foundational documentation and scoping work is already in place.

If you are losing deals because enterprise procurement is asking for a SOC 2 Report, it is not too early. We work with early-stage companies regularly, and the readiness phase is designed to meet you where you are, not assume you have a mature compliance program in place.

The right time to start is when it is costing you customers or adding friction to your sales process.

Perspectives

Latest from Sage Audits

View All Posts